HIPAA applies to you too
Size does not determine whether HIPAA applies to your practice. Function does.
Many small practices assume HIPAA's technical requirements are designed for hospitals and large health systems. That a solo practitioner or small clinic can operate under a lighter standard. This is wrong.
Any covered entity (healthcare providers who transmit health information electronically, health plans, healthcare clearinghouses) or business associate that creates, receives, maintains, or transmits protected health information (PHI) must comply with the HIPAA Security Rule, regardless of size.
If you file electronic claims, send electronic referrals, or use any electronic system to handle patient information, you are a covered entity. The Security Rule applies to you.
The practical reality: HHS Office for Civil Rights (OCR) has investigated and fined practices with fewer than 5 employees. The 2023 OCR enforcement data shows that small practices are disproportionately targeted because they're more likely to have compliance gaps. Being small doesn't reduce your obligations. It increases your risk of being underprepared.
The HIPAA Security Rule in plain English
The Security Rule organizes its requirements into three categories of safeguards. Here's what each one means for how you share files.
Administrative Safeguards
Risk assessment
Identify where PHI lives in your practice, how it moves, and what could go wrong. This is the foundation of everything else.
Workforce training
Every staff member who touches PHI needs to understand the rules, not just the doctor. Front desk, billing, even IT contractors.
Incident response plan
When (not if) something goes wrong, you need a documented plan: who to notify, how to contain the breach, and how to report it to HHS.
Physical Safeguards
Device security
Laptops, tablets, and phones that access PHI need encryption, screen locks, and remote wipe capability. A stolen unencrypted laptop is a reportable breach.
Workstation security
Screens showing PHI should not be visible to patients in the waiting room. Auto-lock after inactivity. No shared logins.
Technical Safeguards
Access controls
Unique user IDs, role-based permissions, automatic logoff. Only the people who need PHI for their job should be able to access it.
Audit controls
Log who accessed what PHI, when, and what they did with it. You need these logs both for compliance and for investigating incidents.
Integrity controls
Mechanisms to confirm PHI hasn't been altered or destroyed improperly. This includes checksums, authentication, and version controls.
Transmission security
PHI in transit must be protected. In practice, this means TLS encryption for any data moving over a network, no exceptions.
The technical safeguards are the most directly relevant to file sharing, but all three categories apply. A compliant file sharing process requires administrative policies, physical device protections, and technical controls working together.
What HIPAA requires for file sharing specifically
When you share files containing PHI, referrals, billing records, insurance documents, lab results. These four requirements are non-negotiable.
Encryption at rest
Addressable (but practically required)HIPAA classifies encryption at rest as "addressable," which does NOT mean optional. It means you must implement it or document why an equivalent alternative is reasonable. For file sharing involving PHI, there is no reasonable alternative to encryption. AES-256 is the standard.
Encryption in transit
RequiredAny PHI moving over a network must be encrypted. TLS 1.2 is the minimum, TLS 1.3 is preferred. This applies to file uploads, downloads, API calls, and email transmissions. If your file sharing tool doesn't enforce HTTPS, it's non-compliant.
Access controls
RequiredYou need to control who can access shared files and verify their identity. Shared folder links with no authentication are a compliance gap. Look for per-file or per-link access restrictions, unique user identification, and automatic access expiration.
Audit trail
RequiredEvery access to PHI must be logged. Who viewed the file, who downloaded it, when, and from where. These logs need to be retained and reviewable. In the event of a breach investigation, HHS will ask for them.
Common HIPAA file sharing mistakes
These are the violations OCR finds most often in small practices, and every one of them is avoidable.
Using personal email for PHI
Gmail, Yahoo, and Outlook.com are not HIPAA-compliant for PHI. Even if the email provider offers encryption, personal accounts lack the administrative controls, audit logging, and BAA coverage that HIPAA requires. PHI in a personal inbox is an open breach.
Texting patient information
Standard SMS is unencrypted, stored on carrier servers, and impossible to audit or revoke. Texting a patient's lab results, diagnosis, or insurance info to a colleague is a HIPAA violation, even if it feels convenient.
Using tools without a BAA
If a vendor handles PHI on your behalf, HIPAA requires a Business Associate Agreement. Using Dropbox, Google Drive, or any file sharing tool without a signed BAA means YOU are liable for any breach on their end. Many tools offer BAAs, but you have to ask.
No audit trail on file access
If you can't answer "who accessed this patient file and when?" you have a compliance gap. Shared folders, USB drives, and consumer file sharing tools typically don't provide the access logging HIPAA requires.
Keeping PHI longer than needed
HIPAA's minimum necessary principle means you should only retain PHI for as long as it's needed for the purpose it was shared. Files sitting in a shared folder indefinitely expand your breach surface with zero benefit.
Tools that can help
No single tool makes you HIPAA compliant, compliance is an organizational responsibility, not a product feature. But the right tools make compliance achievable.
EHR built-in portals
Best for: Clinical data, lab results, patient communication
Best option for clinical workflows. Most EHRs include a patient portal that's already HIPAA-compliant. Limited for sharing with third parties outside your EHR ecosystem.
HIPAA note: Typically covered under your EHR vendor's BAA
Encrypted file transfer (e.g., DeadVault)
Best for: Billing, referrals, insurance docs, third-party sharing
Designed for exchanging documents with external parties: other providers, billing companies, attorneys. Automatic expiration helps enforce retention policies. Not a replacement for your EHR's clinical workflows.
HIPAA note: Requires separate BAA; verify encryption and audit capabilities
Encrypted email (Virtru, Paubox)
Best for: Quick communications, small attachments
Adds encryption to email workflows your staff already know. Good for messages and small files. Large file transfers or structured document exchange can be cumbersome.
HIPAA note: BAA available from most HIPAA-focused email providers
Enterprise platforms (Box, Kiteworks)
Best for: Large organizations, complex permission hierarchies
Full-featured but designed for enterprise IT departments. Can be overkill for a 5-person practice in both cost and complexity. Strong audit and compliance features if you have the staff to manage them.
HIPAA note: BAA available on healthcare/enterprise tiers
Important: Regardless of which tool you choose, you need a signed Business Associate Agreement (BAA) with any vendor that handles PHI on your behalf. The tool itself doesn't make you compliant. Your policies, training, risk assessments, and documentation do. Tools are one component of a compliance program, not a substitute for one.
Frequently asked questions
Common questions about HIPAA file sharing requirements for small practices.
Need secure file sharing for your practice?
DeadVault provides encrypted file transfer with automatic expiration, audit logging, and access controls. It can be one part of your HIPAA compliance toolkit, but remember, compliance starts with your policies and training.